Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions mkosi.conf
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,19 @@ Distribution=ubuntu
Release=resolute
Repositories=main,universe,restricted

[Content]
InitrdProfiles=plymouth
InitrdVolatilePackages=
Comment thread
jumpyvi marked this conversation as resolved.
systemd
udev
systemd-cryptsetup
cryptsetup-bin
bash
coreutils
util-linux
plymouth
plymouth-theme-elementary

[Build]
Comment thread
jumpyvi marked this conversation as resolved.
ToolsTree=default
CacheDirectory=mkosi.cache
Expand Down

This file was deleted.

This file was deleted.

69 changes: 44 additions & 25 deletions mkosi.images/liveiso/mkosi.extra/usr/sbin/elementary-install
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,6 @@ extra="$medium/extra"
raw_squashfs=$(find "$extra" -maxdepth 1 -type f -name '*.raw.squashfs' | head -n1)
repart_src="/opt/repart-target"


# Exit if iso wasnt properly built
if [ -z "$raw_squashfs" ]; then
echo "Installation aborted: No .raw.squashfs file found."
Expand All @@ -18,15 +17,14 @@ fi

echo "Using source image: $raw_squashfs"


# Disk selector
PS3="Select installation disk (ALL DATA WILL BE LOST): "

select selected_disk in $(lsblk -d -n -p -o NAME -e 7,11); do
if [[ -n "$selected_disk" ]]; then
break
fi
echo "Invalid selection, try again."
if [[ -n "$selected_disk" ]]; then
break
fi
echo "Invalid selection, try again."
done

if [ -z "$selected_disk" ]; then
Expand All @@ -36,15 +34,15 @@ fi

dest_dev=$(echo "$selected_disk" | awk '{print $1}')


# Encryption selector
PS3="Select encryption method: "
repart_args=()
keyfile=""

crypt_options=("off")
crypt_options=("off" "passphrase")

# Add tpm option if there is a tpm device
if [ -e /dev/tpm0 ] || [ -e /dev/tpmrm0 ]; then
# Check if systemd thinks you got a good tpm (only "yes", don't show on "partial" and "no")
if [ "$(systemd-analyze has-tpm2 2>/dev/null | head -n1)" = "yes" ]; then
crypt_options+=("tpm2")
fi

Expand All @@ -55,6 +53,27 @@ select crypt in "${crypt_options[@]}"; do
sed -i 's/Encrypt=.*/Encrypt=tpm2/' "$repart_src/40-root.conf"
break
;;
passphrase)
echo "Selected passphrase encryption."
sed -i 's/Encrypt=.*/Encrypt=key-file/' "$repart_src/40-root.conf"
keyfile=$(mktemp)
chmod 600 "$keyfile"

while true; do
IFS= read -rs -p "Enter encryption passphrase: " pass1; echo
IFS= read -rs -p "Confirm passphrase: " pass2; echo
if [ -n "$pass1" ] && [ "$pass1" = "$pass2" ]; then
printf '%s' "$pass1" > "$keyfile"
unset pass1 pass2
break
fi
echo "Passphrases didn't match or were empty, try again."
unset pass1 pass2
done

repart_args+=(--key-file="$keyfile")
break
;;
off)
echo "Encryption disabled."
sed -i 's/Encrypt=.*/Encrypt=off/' "$repart_src/40-root.conf"
Expand All @@ -67,31 +86,30 @@ select crypt in "${crypt_options[@]}"; do
done

echo "$dest_dev selected for repartitioning..."
echo "Destroying drive in 3s ..."
echo "Wiping drive in 3s ..."
sleep 1
echo "Destroying drive in 2s ..."
echo "Wiping drive in 2s ..."
sleep 1
echo "Destroying drive in 1s ..."
echo "Wiping drive in 1s ..."
sleep 1


# Wipe disk, wipefs -a seems to be the most reliable option for this...
# Wipe disk
/usr/sbin/wipefs -a "$dest_dev"


# Mount the squashed sysupdate install image
squash_mount=/mnt/source-image
mkdir -p "$squash_mount"
echo "Mounting compressed image..."
if ! mount -t squashfs -o loop,ro "$raw_squashfs" "$squash_mount"; then
echo "Could not mount image, aborting."
exit 1
echo "Could not mount image, aborting."
exit 1
fi

# Cleanup on exit
cleanup() {
umount "$squash_mount" 2>/dev/null || true
rmdir "$squash_mount" 2>/dev/null || true
umount "$squash_mount" 2>/dev/null || true
rmdir "$squash_mount" 2>/dev/null || true
[ -n "$keyfile" ] && shred -u "$keyfile" 2>/dev/null || true
}
trap cleanup EXIT

Expand All @@ -106,11 +124,12 @@ fi
# The actual install! raw_src has the system partitions, while repart_src has the root partition
echo "Flashing image (efi, root, usr, ...) onto $dest_dev..."
systemd-repart \
--copy-from="$raw_src" \
--definitions="$repart_src/" \
--dry-run=no \
--empty=force \
"$dest_dev"
--copy-from="$raw_src" \
--definitions="$repart_src/" \
--dry-run=no \
--empty=force \
"${repart_args[@]}" \
"$dest_dev"

partprobe "$dest_dev"
udevadm settle
Expand Down
2 changes: 1 addition & 1 deletion mkosi.images/sysupdate/mkosi.conf
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ KernelCommandLine=
mount.usr=dissect
rw
audit=0
systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=unprotected+absent:home=unprotected+absent:=ignore
systemd.image_policy=esp=unprotected:xbootldr=unprotected+unused+absent:usr=signed:root=unprotected+encrypted+absent:home=unprotected+absent:=ignore
systemd.image_filter=usr=elementary_*:usr-verity=elementary_*:usr-verity-sig=elementary_*:root=elementary-*:home=elementary-*
ipe.enforce=0

Expand Down
Loading